To resolve this problem, apply hotfix 961515.
For more information about hotfix 961515, click the following article number to view the article in the Microsoft Knowledge Base:
961515
The subject name of a computer certificate that is issued by a Windows Server 2003-based server is set to the user principal name (UPN) of the computer account after you apply hotfix 943089
Hotfix information
Prerequisites
To apply this hotfix, you must have Windows Server 2003 Service Pack 1 or Windows Server 2003 Service Pack 2 installed on the computer.
For more information, click the following article number to view the article in the Microsoft Knowledge Base:
889100
How to obtain the latest service pack for Windows Server 2003
Restart requirement
You must restart the computer after you apply this hotfix.
Hotfix replacement information
This hotfix is replaced by hotfix 961515.
File information
The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the
Time Zone tab in the
Date and Time item in Control Panel.
Windows Server 2003 with Service Pack 1, x86-based versions
File name | File version | File size | Date | Time | Platform |
---|
Certpdef.dll | 5.2.3790.3017 | 118,272 | 29-Sep-2007 | 05:02 | x86 |
Windows Server 2003 with Service Pack 2, x86-based versions
File name | File version | File size | Date | Time | Platform |
---|
Certpdef.dll | 5.2.3790.4161 | 118,272 | 29-Sep-2007 | 05:11 | x86 |
Windows Server 2003 with Service Pack 1, Itanium-based versions
File name | File version | File size | Date | Time | Platform | SP requirement | Service branch |
---|
Certpdef.dll | 5.2.3790.3017 | 300,032 | 29-Sep-2007 | 02:53 | IA-64 | SP1 | Not applicable |
Wcertpdef.dll | 5.2.3790.3017 | 118,272 | 29-Sep-2007 | 02:53 | x86 | SP1 | WOW |
Windows Server 2003 with Service Pack 2, Itanium-based versions
File name | File version | File size | Date | Time | Platform | SP requirement | Service branch |
---|
Certpdef.dll | 5.2.3790.4161 | 300,032 | 29-Sep-2007 | 03:16 | IA-64 | SP2 | Not applicable |
Wcertpdef.dll | 5.2.3790.4161 | 118,272 | 29-Sep-2007 | 03:16 | x86 | SP2 | WOW |
Windows Server 2003, x64-based versions
File name | File version | File size | Date | Time | Platform | SP requirement | Service branch |
---|
Certpdef.dll | 5.2.3790.3017 | 178,688 | 29-Sep-2007 | 02:53 | x64 | SP1 | Not applicable |
Wcertpdef.dll | 5.2.3790.3017 | 118,272 | 29-Sep-2007 | 02:53 | x86 | SP1 | WOW |
Windows Server 2003 with Service Pack 2, x64-based versions
File name | File version | File size | Date | Time | Platform | SP requirement | Service branch |
---|
Certpdef.dll | 5.2.3790.4161 | 178,688 | 29-Sep-2007 | 03:18 | x64 | SP2 | Not applicable |
Wcertpdef.dll | 5.2.3790.4161 | 118,272 | 29-Sep-2007 | 03:18 | x86 | SP2 | WOW |
This hotfix fixes an issue that occurs when the CT_FLAG_SUBJECT_ALT_REQUIRE_UPN flag is set in a computer template. When this flag is set, the policy module puts the DNS name of the computer in the
Subject Alt Name (SAN) field. This is not the expected behavior. The following behavior occurs after you install the hotfix:
- The first time, the certification authority (CA) policy module queries the explicit UPN attribute of the computer in Active Directory. If the entry in this attribute is found, this entry will be written in the certificate SAN field.
- If no entry is found in the explicit UPN attribute of the computer, the implicit UPN is created by using the samAccountName Active Directory attribute together with the domain name.